haproxy (2.2.9-2+deb11u4) bullseye-security; urgency=high
authorSalvatore Bonaccorso <carnil@debian.org>
Sat, 11 Feb 2023 10:40:49 +0000 (10:40 +0000)
committerSalvatore Bonaccorso <carnil@debian.org>
Sat, 11 Feb 2023 10:40:49 +0000 (10:40 +0000)
commitb28ad220fee83a1c4af7b3ef990c7a58baab79c5
tree9434b80483d298730278b66e88814562ade534ec
parent0f821fd55571e5b9183d1104c9fd0800957353c3
parent964299ba279d4383488b975c648624a5ce8f4501
haproxy (2.2.9-2+deb11u4) bullseye-security; urgency=high

  * Non-maintainer upload by the Security Team.
  * BUG/MEDIUM: mux-h2: Refuse interim responses with end-stream flag set
    (CVE-2023-0056)
  * BUG/CRITICAL: http: properly reject empty http header field names
    (CVE-2023-25725)

[dgit import unpatched haproxy 2.2.9-2+deb11u4]
81 files changed:
debian/NEWS
debian/changelog
debian/clean
debian/control
debian/copyright
debian/dconv/LICENSE
debian/dconv/NOTICE
debian/dconv/README.md
debian/dconv/css/check.png
debian/dconv/css/cross.png
debian/dconv/css/page.css
debian/dconv/haproxy-dconv.py
debian/dconv/img/logo-med.png
debian/dconv/js/typeahead.bundle.js
debian/dconv/parser/__init__.py
debian/dconv/parser/arguments.py
debian/dconv/parser/example.py
debian/dconv/parser/keyword.py
debian/dconv/parser/seealso.py
debian/dconv/parser/table.py
debian/dconv/parser/underline.py
debian/dconv/templates/parser/arguments.tpl
debian/dconv/templates/parser/example.tpl
debian/dconv/templates/parser/example/comment.tpl
debian/dconv/templates/parser/seealso.tpl
debian/dconv/templates/parser/table.tpl
debian/dconv/templates/parser/table/header.tpl
debian/dconv/templates/parser/table/row.tpl
debian/dconv/templates/parser/underline.tpl
debian/dconv/templates/summary.html
debian/dconv/templates/template.html
debian/dconv/tools/generate-docs.sh
debian/gbp.conf
debian/halog.1
debian/haproxy-doc.doc-base.haproxy
debian/haproxy-doc.doc-base.haproxy-lua
debian/haproxy-doc.docs
debian/haproxy-doc.install
debian/haproxy-doc.links
debian/haproxy-doc.maintscript
debian/haproxy.README.Debian
debian/haproxy.cfg
debian/haproxy.default
debian/haproxy.dirs
debian/haproxy.docs
debian/haproxy.examples
debian/haproxy.init
debian/haproxy.install
debian/haproxy.maintscript
debian/haproxy.manpages
debian/haproxy.postinst
debian/haproxy.postrm
debian/haproxy.tmpfile
debian/haproxy.vim
debian/logrotate.conf
debian/patches/0001-2.0-2.3-BUG-MAJOR-htx-fix-missing-header-name-length-check-i.patch
debian/patches/0001-BUG-MAJOR-http-htx-prevent-unbounded-loop-in-http_ma.patch
debian/patches/0001-BUG-MEDIUM-h2-match-absolute-path-not-path-absolute-.patch
debian/patches/0001-BUG-MEDIUM-mux-h2-Refuse-interim-responses-with-end-.patch
debian/patches/0001-BUG-MINOR-tcpcheck-Update-.health-threshold-of-agent.patch
debian/patches/0002-Use-dpkg-buildflags-to-build-halog.patch
debian/patches/2.0-2.5-BUG-CRITICAL-http-properly-reject-empty-http-header-.patch
debian/patches/2.2-0001-MINOR-http-add-a-new-function-http_validate_scheme-t.patch
debian/patches/2.2-0002-BUG-MAJOR-h2-verify-early-that-non-http-https-scheme.patch
debian/patches/2.2-0003-BUG-MAJOR-h2-verify-that-path-starts-with-a-before-c.patch
debian/patches/2.2-0004-BUG-MAJOR-h2-enforce-checks-on-the-method-syntax-bef.patch
debian/patches/2.2-0005-BUG-MEDIUM-h2-give-authority-precedence-over-Host.patch
debian/patches/debianize-dconv.patch
debian/patches/haproxy.service-add-documentation.patch
debian/patches/haproxy.service-start-after-syslog.patch
debian/patches/series
debian/rsyslog.conf
debian/rules
debian/source/format
debian/source/include-binaries
debian/tests/cli
debian/tests/control
debian/tests/proxy-localhost
debian/vim-haproxy.install
debian/vim-haproxy.yaml
debian/watch